CVE-2026-92976: Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0

Published Sep 18, 2026
·
Updated

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data. The content entered is stored and displayed without being properly sanitised when another user, including administrative staff, views the affected profile. Successful exploitation could allow JavaScript code to be executed in the victim’s browser, access to information available within the session, or the performance of actions using the victim’s permissions.

Affected Software

1 affected component
T-Systems TAO 2.0 suite

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade T-Systems TAO 2.0 to a version that resolves this vulnerability.

    Fixed in 2602.0.0

Event History

Sep 18, 2026
CVE Published
via MITRE·09:57 AM
Data Sourced
via MITRE·09:57 AM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Who needs to be able to interact with the vulnerable functionality to exploit this issue?

An attacker needs an authenticated TAO 2.0 account and access to profile-management fields that accept personal-data content. They can store malicious HTML or JavaScript in those fields for execution when another user views the profile.

2

Which users are at risk when a malicious profile is viewed?

Any user who views the affected profile may execute the stored script in their browser, including administrative staff. The impact is bounded by information and actions available through that viewer's active session.

3

How can an organization determine whether it may have been exposed?

Review profile-management personal-data fields for unexpected HTML or JavaScript content, particularly in profiles created or edited by authenticated users. Also investigate administrative or user sessions that viewed profiles containing suspicious stored content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203